SC-200 • Practice Exam 57
Free SC-200 practice exam — 20 questions with explanations. Set 57. No signup required.
During an incident response, a security analyst identifies that a user's account was used to access sensitive data from an anomalous location. The analyst needs to immediately prevent further access from that account while preserving forensic data. Which action should the analyst take?